Social EngineeringPhishingBECCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Rowhouse Financial Partners
bd_ef3e688ab3e45437 · schema v1 · pii pii-v1
Full breach record for Rowhouse Financial Partners →Rowhouse Financial Partners notified the Maryland AG of a business email compromise affecting 16 residents. An unauthorized person accessed an employee email account on Dec 6, 2024, viewing names, SSNs, and financial account info. RFP secured the account, enhanced policies, provided 12 months of credit monitoring, and notified affected individuals.
Maryland clock⏱ MD AG >30d8 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed16 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376277.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2025
- Raw hash
- 3f10913dd612118b523a0d0bf34529526f10338fdc66e11bf767eac3a89dd7e9
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Rowhouse Financial Partnersnorm: rowhouse financial
Incident
- Discovered
- Dec 6, 2024
- Materiality determined
- Jan 30, 2025
- Notification sent
- Jan 30, 2025
- Affected individuals
- 16
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided written notice to Maryland Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- MD AG >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.